Netinfo Security ›› 2024, Vol. 24 ›› Issue (7): 1122-1128.doi: 10.3969/j.issn.1671-1122.2024.07.013

Previous Articles     Next Articles

Research on APT Attack Defense System Based on Threat Discovery

ZHAO Xinqiang1,2, FAN Bo1(), ZHANG Dongju1   

  1. 1. China Electronic Standardization Institute, Beijing 100007, China
    2. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100085, China
  • Received:2024-03-06 Online:2024-07-10 Published:2024-08-02

Abstract:

The unknown and uncertainty of APT attacks make it difficult for traditional defense systems to quickly detect and defend, and their continuous evolution ability also makes traditional defense methods based on feature detection technology inadequate. This paper presented an APT attack and defense model based on the concept of red-blue confrontation, and summarized the steps and techniques of common network attacks based on the classification of kill chains. It also proposed a defense concept model with the core of APT threat discovery and a comprehensive security technology framework of “cloud, management, end, and ground” collaboration based on the practical experience of APT attack and defense.

Key words: cyberspace security, APT, unknown attack, red-blue confrontation, threat discovery

CLC Number: